You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/alerts-reference.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -324,7 +324,7 @@ Microsoft Defender for Containers provides security alerts on the cluster level
324
324
325
325
<sup><aname="footnote1"></a>1</sup>: **Preview for non-AKS clusters**: This alert is generally available for AKS clusters, but it is in preview for other environments, such as Azure Arc, EKS and GKE.
326
326
327
-
<sup><aname="footnote2"></a>2</sup>: **Limitations on GKE clusters**: GKE uses a Kuberenetes audit policy that doesn't support all alert types. As a result, this security alert, which is based on Kubernetes audit events, is not supported for GKE clusters.
327
+
<sup><aname="footnote2"></a>2</sup>: **Limitations on GKE clusters**: GKE uses a Kubernetes audit policy that doesn't support all alert types. As a result, this security alert, which is based on Kubernetes audit events, is not supported for GKE clusters.
328
328
329
329
<sup><aname="footnote3"></a>3</sup>: This alert is supported on Windows nodes/containers.
330
330
@@ -686,7 +686,7 @@ VM.Windows_CommandLineStartingAllExe | Detected suspicious command line used to
686
686
VM.Windows_DisablingAndDeletingIISLogFiles | Detected actions indicative of disabling and deleting IIS log files | Medium
687
687
VM.Windows_DownloadUsingCertutil | Suspicious download using Certutil detected | Medium
688
688
VM.Windows_EchoOverPipeOnLocalhost | Detected suspicious named pipe communications | High
689
-
VM.Windows_EchoToConstructPowerShellScript | Dynamic PS script construction | Medium
689
+
VM.Windows_EchoToConstructPowerShellScript | Dynamic PowerShell script construction | Medium
690
690
VM.Windows_ExecutableDecodedUsingCertutil | Detected decoding of an executable using built-in certutil.exe tool | Medium
691
691
VM.Windows_FileDeletionIsSospisiousLocation | Suspicious file deletion detected | Medium
692
692
VM.Windows_KerberosGoldenTicketAttack | Suspected Kerberos Golden Ticket attack parameters observed | Medium
VM_ProcessWithDoubleExtensionExecution | Suspicious double extension file executed | High
721
721
VM_RegistryPersistencyKey | Windows registry persistence method detected | Low
722
722
VM_ShadowCopyDeletion | Suspicious Volume Shadow Copy Activity <br/> Executable found running from a suspicious location | High
723
-
VM_SuspectExecutablePath | Executable found running from a suspicious location <br/> Detected anomoalous mix of uppercase and lowercase characters in command line | Informational <br/> <br/> Medium <br/> |
723
+
VM_SuspectExecutablePath | Executable found running from a suspicious location <br/> Detected anomalous mix of uppercase and lowercase characters in command line | Informational <br/> <br/> Medium <br/> |
724
724
VM_SuspectPhp | Suspicious PHP execution detected | Medium
725
725
VM_SuspiciousCommandLineExecution | Suspicious command execution | High
726
726
VM_SuspiciousScreenSaverExecution | Suspicious Screensaver process executed | Medium
0 commit comments